USN-7678-1: Perl vulnerability
USN-7678-1: Perl vulnerability
Publication date: 29 July 2025
Overview: Perl could be made to target unintended paths when performing file operations.
Packages
perl - Practical Extraction and Report Language
Details
It was discovered that Perl threads incorrectly handled certain file
operations. A local attacker could possibly use this issue to load code or
access files from unexpected locations.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu Release Package Version
- 25.04 plucky perl – 5.40.1-2ubuntu0.2
- 24.04 noble perl – 5.38.2-3.2ubuntu0.2
- 22.04 jammy perl – 5.34.0-3ubuntu1.5